spring-projects / spring-projects/spring-security
SEC-2148: AccessDecisionVoters should return an AccessDecision instead of int
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Janning Vygen (Migrated from SEC-2148) said:
An AccessDecisionManager throws an AccessDeniedException (ADE) which is handled later by an ExceptionTranslationFilter and AccessDeniedHandler. Inside AccessDeniedHandler we would like to forward to different error pages depending on the cause of the ADE.
But the AccessDecisionManager is just asking AccessDecisionVoter and it just returns an int for ACCESS_GRANTED or ACCESS_DENIED. It would be nice if an AccessDecisionVoter would return an AccessDecision which can hold the pure decision like granted/denied and a cause if the access was denied.
The AccessDecisionManager could then throw an ADE containing the accessDecision. The AccessDeniedHandler can grab this decision and decide what to show to the user.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the AccessDecisionVoter and AccessDecisionManager entry points described in the issue, then trace how AccessDeniedException reaches ExceptionTranslationFilter and AccessDeniedHandler. Determine the API and compatibility changes needed for a decision carrying a denial cause; done means the handler can distinguish denial causes while existing access decisions remain supported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100